About IVRE
IVRE, a French acronym also read as Dynamic Recon of UNKnown networks, is a network reconnaissance framework with tools for both passive and active recon. It lets security teams build their own, fully controlled alternatives to services like Shodan, ZoomEye, Censys and GreyNoise.
It ingests data from passive sources such as Zeek, Argus, Nfdump, p0f and airodump-ng, and from active tools including Nmap, Masscan, ZGrab2, ZDNS, Nuclei, httpx, dnsx, tlsx and Dismap. Uses listed by the project include running a passive DNS service, assembling a tailor-made external attack surface management tool, and collecting and analyzing network intelligence from your own sensors. Topics reference Nmap result analysis and OSINT.
IVRE is written in Python and licensed under GPL-3.0, and runs on your own infrastructure. It suits security researchers and defenders who work on networks they are authorized to scan. As with any scanning tool, use it only where you have permission.
Key features
- Passive recon from Zeek and p0f data
- Active scanning with Nmap and Masscan
- Integration with Nuclei and httpx
- Passive DNS service capability
- External attack surface management
- Searchable network intelligence database
Good fit for
- →Building a private Shodan-like search
- →Attack surface monitoring
- →Analyzing Nmap scan results at scale
- Built with
- Python
- Tags
- network-recon
- security
- nmap
- osint
- easm
- zeek
- python
- passive-dns
IVRE: questions and answers
- What is IVRE used for?
- IVRE is a Python network reconnaissance framework that collects and analyzes scan and passive data, for building self-hosted alternatives to Shodan or Censys. It is a good fit for building a private Shodan-like search, attack surface monitoring and analyzing Nmap scan results at scale.
- Is IVRE open source?
- Yes. IVRE is open source under the GPL-3.0 licence. Its source code is on GitHub at ivre/ivre and is written mainly in Python.
- Is IVRE free?
- Yes. IVRE is open source, so the software itself is free to use.
- Can I self-host IVRE?
- Yes. IVRE can be self-hosted on your own server or infrastructure; there is no official hosted version.
- Is IVRE actively maintained?
- Yes. The most recent commit to IVRE was on 1 October 2026, and the latest release is v0.9.21, published on 25 September 2024. The project has 4.2k stars on GitHub.
Open-source alternatives to IVRE
See all
fail2ban
Security
Daemon to ban hosts that cause multiple authentication errors
OSS★ 19k
DefectDojo
Security
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
BSD-3-Clausevs Tenable★ 5k
Security Onion
Security
Security Onion is a free and open platform for threat hunting, enterprise security monitor
OSSvs Splunk★ 4.9k
CISO Assistant
Security
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & A
OSSvs Vanta★ 4.5kOminis-OSINT
Security
This Python application is an OSINT (Open Source Intelligence) tool called "Ominis OSINT -
MIT★ 626email2phonenumber
Security
A OSINT tool to obtain a target's phone number just by having his email address
MIT★ 2.8k
SaaS alternatives to IVRE
See all
Shodan
Security
Search engine for internet-connected devices, open ports and service banners
SaaS
Censys
Security
Internet scanning data and attack surface management platform
SaaS
AttackerView
Security
Security auditor that shows what an attacker can see on your website
SaaS
Recorded Future
Security
Threat intelligence platform
SaaS
Intruder
Security
Cloud-based vulnerability scanner for external attack surface
SaaS
Abnormal Security
Security
Behavior-based cloud email security that blocks phishing and account takeover
SaaS

